Description
Contributor Cross Site Scripting (XSS) in Strong Testimonials <= 3.3.11 versions.
Published: 2026-09-30
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Cross‑Site Scripting (XSS)
Action: Immediate patch
AI Analysis

Impact

The vulnerability is a Contributor Cross‑Site Scripting flaw in the WordPress Strong Testimonials plugin up to version 3.3.11. It allows an attacker to inject malicious script through an untrusted input field, potentially subverting the integrity of the site’s content and enabling further exploitation such as session hijacking or defacement. The weakness falls under input validation failure (CWE‑79).

Affected Systems

Affected systems are installations of the WP Chill Strong Testimonials plugin running any version up to and including 3.3.11. The vulnerability manifests when the plugin is enabled on a WordPress site and the contributor form or similar input gateway is exposed to the web. No specific WordPress core or theme version is mentioned.

Risk and Exploitability

The CVSS base score of 6.5 indicates a medium severity with potential for client‑side impact. Because the EPSS score is not available, the exploitation probability is unclear but the lack of limited scope mitigations may make the flaw attractive to opportunistic attackers. As of now the vulnerability is not listed in the CISA KEV catalog, however, the absence of a listing does not preclude active exploitation, and the plugin vendor has issued a fix in version 3.3.12. The likely attack vector is a web‑based submission of malformed input through the plugin’s contributor interface.

Generated by OpenCVE AI on September 30, 2026 at 15:01 UTC.

Remediation

Vendor Solution

Update the WordPress Strong Testimonials plugin to the latest available version (at least 3.3.12).


OpenCVE Recommended Actions

  • Upgrade the Strong Testimonials plugin to version 3.3.12 or later where input sanitisation has been fixed.
  • Confirm the plugin now serves only sanitized data by testing the contributor form or reviewing the plugin files for legacy callbacks.
  • Implement or enable a web application firewall rule that blocks typical XSS payloads, such as script tags or event handlers, in posts or form submissions on the site.

Generated by OpenCVE AI on September 30, 2026 at 15:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description Contributor Cross Site Scripting (XSS) in Strong Testimonials <= 3.3.11 versions.
Title WordPress Strong Testimonials plugin <= 3.3.11 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-30T13:37:19.009Z

Reserved: 2026-09-24T10:23:27.495Z

Link: CVE-2026-97286

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-30T13:17:38.813

Modified: 2026-09-30T14:18:17.683

Link: CVE-2026-97286

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T15:15:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')